Skip to content

Bouncy Castle cryptography: .NET 10, OAEP, 2048-bit DSA, derived Blowfish key - #2273

Merged
vladimir-pecanac-main merged 2 commits into
CodeMazeBlog:mainfrom
vladimir-pecanac-main:seo/116968-csharp-bouncy-castle-cryptography
Oct 9, 2026
Merged

vladimir-pecanac-main merged 2 commits into
CodeMazeBlog:mainfrom
vladimir-pecanac-main:seo/116968-csharp-bouncy-castle-cryptography

Conversation

@vladimir-pecanac-main

Copy link
Copy Markdown
Collaborator

Updates the sample for the Code Maze article "Bouncy Castle Cryptography in C# and .NET" (https://code-maze.com/csharp-bouncy-castle-cryptography/). Only authorization-dotnet/BouncyCastleCryptography changes.

Packages (re-queried on NuGet 2026-10-09; the re-query wins over the batch block):

  • BouncyCastle.Cryptography 2.3.1 to 2.7.0 (latest, MIT, published 2026-07-30)
  • Microsoft.NET.Test.Sdk 17.8.0 to 18.10.1 (batch block said 18.10.0)
  • coverlet.collector 6.0.0 to 10.1.0 (batch block said 10.0.1)
  • MSTest.TestAdapter and MSTest.TestFramework 3.1.1 to 4.5.1 (batch block said 4.4.0); MSTest kept, no test calls ThrowsException
  • both projects net8.0 to net10.0

Code:

  • RSA: OaepEncoding(new RsaEngine(), new Sha256Digest()) replaces Pkcs1Encoding.
  • DSA: DsaParametersGenerator(new Sha256Digest()) with DsaParameterGenerationParameters(2048, 256, 80, random). The old Init(size, certainty, random) overload rejects anything above 1024 bits.
  • Blowfish: the password goes through PBKDF2 (HMAC-SHA256, 600,000 iterations, random 16-byte salt) to a 128-bit key instead of being used as the key bytes. Encrypt and decrypt now take the salt. Static class, file-scoped namespace, redundant usings removed.
  • AesDecrypt returns directly, matching the article snippet.
  • Program.cs hashes the article input string and prints the DSA signature (it printed the Blowfish ciphertext under that label).
  • Tests: "pasword" typo fixed, MD5 and SHA-256 known-answer tests added, unused out values discarded.

Local run (SDK 10.0.302, runtime 10.0.10): build 0 warnings 0 errors, 12 of 12 tests passed, dotnet list package --vulnerable --include-transitive clean on both projects.

…fish key

- Retarget both projects to net10.0; BouncyCastle.Cryptography 2.3.1 to 2.7.0;
  Microsoft.NET.Test.Sdk 18.10.1, coverlet.collector 10.1.0, MSTest 4.5.1.
- RSA: Pkcs1Encoding to OaepEncoding over SHA-256.
- DSA: 2048-bit parameters through DsaParameterGenerationParameters
  (the Init(size, certainty) overload stops at 1024 bits).
- Blowfish: derive the key from the password with PBKDF2 (HMAC-SHA256,
  random salt) instead of using the password bytes as the key; static class,
  file-scoped namespace, redundant usings removed.
- Program.cs: hash the article's input string and print the DSA signature
  instead of the Blowfish ciphertext.
- Tests: fix the "pasword" typo, add MD5 and SHA-256 known-answer tests,
  discard unused out values.
@vladimir-pecanac-main
vladimir-pecanac-main merged commit 9d6b70c into CodeMazeBlog:main Oct 9, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant