diff options
| author | tb <> | 2024-03-17 07:10:00 +0000 | 
|---|---|---|
| committer | tb <> | 2024-03-17 07:10:00 +0000 | 
| commit | d1ab59206a7f50aee168d077e40fa7723efbd1d2 (patch) | |
| tree | cb438d8d5a23a69148e0a6f042dba0d35afb6328 /src/lib/libssl/man/SSL_CTX_ctrl.3 | |
| parent | 867e80a6872b3ba4a6625c024b19d5ba20164111 (diff) | |
| download | openbsd-d1ab59206a7f50aee168d077e40fa7723efbd1d2.tar.gz openbsd-d1ab59206a7f50aee168d077e40fa7723efbd1d2.tar.bz2 openbsd-d1ab59206a7f50aee168d077e40fa7723efbd1d2.zip | |
Annotate RSA-PSS SHA parameter encoding as wrong
A historic blunderfest in the ASN.1 module for RSA-PSS led to very
confusing text in various RFCs. davidben and my current reading of
this is that parameters for SHA-* should be encoded as an ASN.1 NULL
rather than omitted. The use of X509_ALGOR_set_evp_md() leads to them
being omitted, and is therefore counter to the specification (but
allowed. We should fix this. For now, leave a reminder.
See https://boringssl-review.googlesource.com/c/boringssl/+/67088
for a lot more details.
ok davidben
Diffstat (limited to 'src/lib/libssl/man/SSL_CTX_ctrl.3')
0 files changed, 0 insertions, 0 deletions
