summaryrefslogtreecommitdiff
path: root/src/lib/libssl/man/SSL_get_finished.3
diff options
context:
space:
mode:
authortb <>2024-03-17 07:10:00 +0000
committertb <>2024-03-17 07:10:00 +0000
commitd1ab59206a7f50aee168d077e40fa7723efbd1d2 (patch)
treecb438d8d5a23a69148e0a6f042dba0d35afb6328 /src/lib/libssl/man/SSL_get_finished.3
parent867e80a6872b3ba4a6625c024b19d5ba20164111 (diff)
downloadopenbsd-d1ab59206a7f50aee168d077e40fa7723efbd1d2.tar.gz
openbsd-d1ab59206a7f50aee168d077e40fa7723efbd1d2.tar.bz2
openbsd-d1ab59206a7f50aee168d077e40fa7723efbd1d2.zip
Annotate RSA-PSS SHA parameter encoding as wrong
A historic blunderfest in the ASN.1 module for RSA-PSS led to very confusing text in various RFCs. davidben and my current reading of this is that parameters for SHA-* should be encoded as an ASN.1 NULL rather than omitted. The use of X509_ALGOR_set_evp_md() leads to them being omitted, and is therefore counter to the specification (but allowed. We should fix this. For now, leave a reminder. See https://boringssl-review.googlesource.com/c/boringssl/+/67088 for a lot more details. ok davidben
Diffstat (limited to 'src/lib/libssl/man/SSL_get_finished.3')
0 files changed, 0 insertions, 0 deletions