Blame SOURCES/python-rsa-to-cryptography.patch

4556b9
diff -uNr a/awscli/customizations/cloudfront.py b/awscli/customizations/cloudfront.py
4556b9
--- a/awscli/customizations/cloudfront.py	2017-08-12 01:39:00.000000000 +0200
4556b9
+++ b/awscli/customizations/cloudfront.py	2018-01-05 09:40:09.445445687 +0100
4556b9
@@ -14,7 +14,9 @@
4556b9
 import time
4556b9
 import random
4556b9
 
4556b9
-import rsa
4556b9
+from cryptography.hazmat.primitives import serialization, hashes
4556b9
+from cryptography.hazmat.primitives.asymmetric import padding
4556b9
+from cryptography.hazmat.backends import default_backend
4556b9
 from botocore.utils import parse_to_aware_datetime
4556b9
 from botocore.signers import CloudFrontSigner
4556b9
 
4556b9
@@ -254,7 +256,10 @@
4556b9
 
4556b9
 class RSASigner(object):
4556b9
     def __init__(self, private_key):
4556b9
-        self.priv_key = rsa.PrivateKey.load_pkcs1(private_key.encode('utf8'))
4556b9
+        self.priv_key = serialization.load_pem_private_key(
4556b9
+            private_key.encode('utf8'), password=None,
4556b9
+            backend=default_backend())
4556b9
 
4556b9
     def sign(self, message):
4556b9
-        return rsa.sign(message, self.priv_key, 'SHA-1')
4556b9
+        return self.priv_key.sign(
4556b9
+            message, padding.PKCS1v15(), hashes.SHA1())
4556b9
diff -uNr a/awscli/customizations/cloudtrail/validation.py b/awscli/customizations/cloudtrail/validation.py
4556b9
--- a/awscli/customizations/cloudtrail/validation.py	2017-08-12 01:39:00.000000000 +0200
4556b9
+++ b/awscli/customizations/cloudtrail/validation.py	2018-01-04 17:04:38.869212582 +0100
4556b9
@@ -22,8 +22,10 @@
4556b9
 from datetime import datetime, timedelta
4556b9
 from dateutil import tz, parser
4556b9
 
4556b9
-from pyasn1.error import PyAsn1Error
4556b9
-import rsa
4556b9
+from cryptography.hazmat.primitives import serialization, hashes
4556b9
+from cryptography.hazmat.backends import default_backend
4556b9
+from cryptography.hazmat.primitives.asymmetric import padding
4556b9
+from cryptography.exceptions import InvalidSignature
4556b9
 
4556b9
 from awscli.customizations.cloudtrail.utils import get_trail_by_arn, \
4556b9
     get_account_id_from_arn
4556b9
@@ -530,20 +532,18 @@
4556b9
         """
4556b9
         try:
4556b9
             decoded_key = base64.b64decode(public_key)
4556b9
-            public_key = rsa.PublicKey.load_pkcs1(decoded_key, format='DER')
4556b9
+            public_key = serialization.load_der_public_key(decoded_key,
4556b9
+                backend=default_backend())
4556b9
             to_sign = self._create_string_to_sign(digest_data, inflated_digest)
4556b9
             signature_bytes = binascii.unhexlify(digest_data['_signature'])
4556b9
-            rsa.verify(to_sign, signature_bytes, public_key)
4556b9
-        except PyAsn1Error:
4556b9
+            public_key.verify(signature_bytes, to_sign, padding.PKCS1v15(),
4556b9
+                hashes.SHA256())
4556b9
+        except (ValueError, TypeError):
4556b9
             raise DigestError(
4556b9
                 ('Digest file\ts3://%s/%s\tINVALID: Unable to load PKCS #1 key'
4556b9
                  ' with fingerprint %s')
4556b9
                 % (bucket, key, digest_data['digestPublicKeyFingerprint']))
4556b9
-        except rsa.pkcs1.VerificationError:
4556b9
-            # Note from the Python-RSA docs: Never display the stack trace of
4556b9
-            # a rsa.pkcs1.VerificationError exception. It shows where in the
4556b9
-            # code the exception occurred, and thus leaks information about
4556b9
-            # the key.
4556b9
+        except InvalidSignature:
4556b9
             raise DigestSignatureError(bucket, key)
4556b9
 
4556b9
     def _create_string_to_sign(self, digest_data, inflated_digest):
4556b9
diff -uNr a/awscli/customizations/ec2/decryptpassword.py b/awscli/customizations/ec2/decryptpassword.py
4556b9
--- a/awscli/customizations/ec2/decryptpassword.py	2017-08-12 01:39:00.000000000 +0200
4556b9
+++ b/awscli/customizations/ec2/decryptpassword.py	2018-01-04 16:24:42.565140244 +0100
4556b9
@@ -13,7 +13,9 @@
4556b9
 import logging
4556b9
 import os
4556b9
 import base64
4556b9
-import rsa
4556b9
+from cryptography.hazmat.primitives import serialization
4556b9
+from cryptography.hazmat.backends import default_backend
4556b9
+from cryptography.hazmat.primitives.asymmetric import padding
4556b9
 from awscli.compat import six
4556b9
 
4556b9
 from botocore import model
4556b9
@@ -109,9 +111,11 @@
4556b9
             try:
4556b9
                 with open(self._key_path) as pk_file:
4556b9
                     pk_contents = pk_file.read()
4556b9
-                    private_key = rsa.PrivateKey.load_pkcs1(six.b(pk_contents))
4556b9
+                    private_key = serialization.load_pem_private_key(
4556b9
+                        six.b(pk_contents), password=None,
4556b9
+                        backend=default_backend())
4556b9
                     value = base64.b64decode(value)
4556b9
-                    value = rsa.decrypt(value, private_key)
4556b9
+                    value = private_key.decrypt(value, padding.PKCS1v15())
4556b9
                     logger.debug(parsed)
4556b9
                     parsed['PasswordData'] = value.decode('utf-8')
4556b9
                     logger.debug(parsed)