This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 44 · Oct 27 – Nov 2, 2025

crypto/rsa: deprecate PKCS #1 v1.5 encryption

Worth knowingstdlib

What changed
The proposal to deprecate PKCS #1 v1.5 encryption for RSA has been accepted and added to the active proposals list.
Production impact
The source does not say.
Try it
Review your code for calls to EncryptPKCS1v15 and consider migrating to RSA‑OAEP.
Source
github.com/golang/go/issues/75302

Understand it, then run it

The crypto/rsa package in Go used to provide a function called EncryptPKCS1v15 for encrypting data with RSA. That function used a padding scheme from PKCS #1 v1.5. The new change marks that function as *deprecated*. Deprecation means the function still works, but developers are warned that it is unsafe and should not be used. The recommendation is to switch to EncryptOAEP and DecryptOAEP, which use a safer padding scheme.

Run it now

Todaygo
// This program demonstrates the deprecation warning for RSA PKCS#1 v1.5 encryption.
// It uses the standard library only and runs in Go 1.27.1.
// The EncryptPKCS1v15 function still exists but is marked Deprecated.
// The compiler will emit a warning when this function is called.

package main

import (
	"crypto/rand"
	"crypto/rsa"
	"fmt"
)

func main() {
	// Generate a 2048‑bit RSA key for demonstration.
	priv, err := rsa.GenerateKey(rand.Reader, 2048)
	if err != nil {
		panic(err)
	}

	// Message to encrypt; must be shorter than the modulus minus 11 bytes.
	msg := []byte("Hello, RSA PKCS#1 v1.5")

	// Call the deprecated EncryptPKCS1v15 function.
	ciphertext, err := rsa.EncryptPKCS1v15(rand.Reader, &priv.PublicKey, msg)
	if err != nil {
		panic(err)
	}

	// Decrypt the ciphertext using the deprecated DecryptPKCS1v15 function.
	plain, err := rsa.DecryptPKCS1v15(rand.Reader, priv, ciphertext)
	if err != nil {
		panic(err)
	}

	fmt.Printf("Original: %s\nDecrypted: %s\n", msg, plain)
}

What it printed when we ran it on Go 1.27.1

Original: Hello, RSA PKCS#1 v1.5
Decrypted: Hello, RSA PKCS#1 v1.5

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed