Radar · Go · Archive · Week 50 · Dec 8 – 14, 2025
crypto/rsa: allow hash.Hash for OAEP and MGF1 to be specified independently for encryption
Worth knowingstdlib
- What changed
- The proposal adds
EncryptOAEPWithOptions, a function that accepts separate hash functions for OAEP and MGF1 in RSA-OAEP encryption. - Production impact
- The source does not say.
- Try it
- In a future release, call
rsa.EncryptOAEPWithOptionswith customOAEPOptionsto encrypt data using SHA‑256 for OAEP and SHA‑1 for MGF1. - Source
- github.com/golang/go/issues/65716
Understand it, then run it
Run it now
// This program demonstrates the current limitation of rsa.EncryptOAEP in Go 1.27.1:
// it requires the same hash function for both OAEP and MGF1. The new
// EncryptOAEPWithOptions function, which would allow independent hash
// selection, is not yet available. The code below uses the standard
// EncryptOAEP with a single hash function (sha256) for both roles.
package main
import (
"crypto/rand"
"crypto/rsa"
"crypto/sha256"
"fmt"
)
func main() {
// Generate a temporary RSA key pair for demonstration.
priv, err := rsa.GenerateKey(rand.Reader, 2048)
if err != nil {
panic(err)
}
// The message to encrypt (e.g., a 256‑bit AES key).
msg := []byte("example 256‑bit AES key for demonstration")
// Encrypt using RSA-OAEP with SHA‑256 for both OAEP and MGF1.
ciphertext, err := rsa.EncryptOAEP(sha256.New(), rand.Reader, &priv.PublicKey, msg, nil)
if err != nil {
panic(err)
}
// Decrypt to verify correctness.
plain, err := rsa.DecryptOAEP(sha256.New(), rand.Reader, priv, ciphertext, nil)
if err != nil {
panic(err)
}
fmt.Printf("original: %s\n", msg)
fmt.Printf("decrypted: %s\n", plain)
}
What it printed when we ran it on Go 1.27.1
original: example 256‑bit AES key for demonstration decrypted: example 256‑bit AES key for demonstration
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed