Skip to content

Multiple diffieHellman.generateKeys calls don't update the public key #56990

Description

@toramanomer

Affected URL(s)

https://nodejs.org/docs/latest-v22.x/api/crypto.html#diffiehellmangeneratekeysencoding

Description of the problem

The documentation regarding diffieHellman.generateKeys([encoding]) in crypto module states as follows:

This function is a thin wrapper around DH_generate_key(). In particular, once a private key has been generated or set, calling this function only updates the public key but does not generate a new private key.

I have not been able to observe in any way that calling generateKeys multiple times results in different public keys.

import { createDiffieHellman } from 'node:crypto'

const alice = createDiffieHellman(1024)
const public1 = alice.generateKeys('hex')
const public2 = alice.generateKeys('hex')
const public3 = alice.generateKeys('hex')

console.log(public1 === public2)     // true
console.log(public1 === public3)     // true
console.log(public2 === public3)    // true

NodeJS docs state that it is a thin wrapper around OpenSSL's DH_generate_key. The OpenSSL page on DH_generate_key states that as follows in their docs:

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_derive_init(3) and EVP_PKEY_derive(3).

Is it possible this is the result of such deprecation?

Activity

  1. added
    docIssues and PRs related to Node.js documentation.
    on Feb 10, 2025
  2. bnoordhuis commented on Feb 11, 2025

    @bnoordhuis
    Member

    Not a bug but maybe a case of unclear documentation. See commit 4a82c8f for why that paragraph was added.

    Public key generation is a deterministic process. You don't change any parameters so of course the public key stays the same. If you called dh.setPublicKey(some_other_pubkey) and then call generateKeys again, you get the old public key again.

  3. github-actions commented on Apr 21, 2026

    @github-actions
    Contributor

    This issue has been marked as stale due to 210 days of inactivity.
    It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.

  4. added
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Apr 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cryptoIssues and PRs related to the crypto subsystem.docIssues and PRs related to Node.js documentation.staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions