Summary
In internal/oidc/azure_signer.go resolveOnce, the signer fetches the EC public key by reading resp.Key.X and resp.Key.Y and constructs an *ecdsa.PublicKey with the curve hardcoded to elliptic.P256(), without validating the resp.Key.Crv field.
If someone misconfigures a P-384 or P-521 key in Key Vault:
PublicKey() will return a key with P-256 curve but P-384/P-521 coordinate sizes, which is an invalid point on P-256.
- The
Sign call will return an error (Key Vault rejects ES256 signing with a non-P-256 key), so no silently wrong signatures are produced.
The gap is that the error surfaces at sign-time rather than at key-fetch time, and the public key returned by PublicKey() is structurally invalid.
Fix: check resp.Key.Crv != nil && *resp.Key.Crv == azkeys.CurveNameP256 in resolveOnce and return an error if the curve is absent or not P-256.
This is a correctness issue but low severity in practice because Azure Key Vault enforces the algorithm on Sign. Discovered during adversarial review of PR LeanerCloud/cloud-commitments-cli#882.
Summary
In
internal/oidc/azure_signer.goresolveOnce, the signer fetches the EC public key by readingresp.Key.Xandresp.Key.Yand constructs an*ecdsa.PublicKeywith the curve hardcoded toelliptic.P256(), without validating theresp.Key.Crvfield.If someone misconfigures a P-384 or P-521 key in Key Vault:
PublicKey()will return a key with P-256 curve but P-384/P-521 coordinate sizes, which is an invalid point on P-256.Signcall will return an error (Key Vault rejects ES256 signing with a non-P-256 key), so no silently wrong signatures are produced.The gap is that the error surfaces at sign-time rather than at key-fetch time, and the public key returned by
PublicKey()is structurally invalid.Fix: check
resp.Key.Crv != nil && *resp.Key.Crv == azkeys.CurveNameP256inresolveOnceand return an error if the curve is absent or not P-256.This is a correctness issue but low severity in practice because Azure Key Vault enforces the algorithm on Sign. Discovered during adversarial review of PR LeanerCloud/cloud-commitments-cli#882.