summaryrefslogtreecommitdiff
path: root/src/lib/libtls/tls_signer.c
diff options
context:
space:
mode:
authortb <>2023-04-09 18:26:26 +0000
committertb <>2023-04-09 18:26:26 +0000
commit3f534e9f9450f122637aed8d48c9f569cdcbdd94 (patch)
tree39afd096589ed359614e27170d552525f638aace /src/lib/libtls/tls_signer.c
parent1a13fc28a37c78be82ff302230a5b50d3ea03d28 (diff)
downloadopenbsd-3f534e9f9450f122637aed8d48c9f569cdcbdd94.tar.gz
openbsd-3f534e9f9450f122637aed8d48c9f569cdcbdd94.tar.bz2
openbsd-3f534e9f9450f122637aed8d48c9f569cdcbdd94.zip
Drop X9.31 support from libtls
The TLS signer isn't exposed in public API (we should finally fix it...) and it supports X9.31, a standard that has been retired and deprecated for a very long time. libcrypto will stop supporting it soon, this step is needed to prepare userland. ok jsing
Diffstat (limited to 'src/lib/libtls/tls_signer.c')
-rw-r--r--src/lib/libtls/tls_signer.c6
1 files changed, 1 insertions, 5 deletions
diff --git a/src/lib/libtls/tls_signer.c b/src/lib/libtls/tls_signer.c
index 1f11096792..f6005d3e07 100644
--- a/src/lib/libtls/tls_signer.c
+++ b/src/lib/libtls/tls_signer.c
@@ -1,4 +1,4 @@
1/* $OpenBSD: tls_signer.c,v 1.4 2022/02/01 17:18:38 jsing Exp $ */ 1/* $OpenBSD: tls_signer.c,v 1.5 2023/04/09 18:26:26 tb Exp $ */
2/* 2/*
3 * Copyright (c) 2021 Eric Faurot <eric@openbsd.org> 3 * Copyright (c) 2021 Eric Faurot <eric@openbsd.org>
4 * 4 *
@@ -193,8 +193,6 @@ tls_sign_rsa(struct tls_signer *signer, struct tls_signer_key *skey,
193 rsa_padding = RSA_NO_PADDING; 193 rsa_padding = RSA_NO_PADDING;
194 } else if (padding_type == TLS_PADDING_RSA_PKCS1) { 194 } else if (padding_type == TLS_PADDING_RSA_PKCS1) {
195 rsa_padding = RSA_PKCS1_PADDING; 195 rsa_padding = RSA_PKCS1_PADDING;
196 } else if (padding_type == TLS_PADDING_RSA_X9_31) {
197 rsa_padding = RSA_X931_PADDING;
198 } else { 196 } else {
199 tls_error_setx(&signer->error, "invalid RSA padding type (%d)", 197 tls_error_setx(&signer->error, "invalid RSA padding type (%d)",
200 padding_type); 198 padding_type);
@@ -331,8 +329,6 @@ tls_rsa_priv_enc(int from_len, const unsigned char *from, unsigned char *to,
331 padding_type = TLS_PADDING_NONE; 329 padding_type = TLS_PADDING_NONE;
332 } else if (rsa_padding == RSA_PKCS1_PADDING) { 330 } else if (rsa_padding == RSA_PKCS1_PADDING) {
333 padding_type = TLS_PADDING_RSA_PKCS1; 331 padding_type = TLS_PADDING_RSA_PKCS1;
334 } else if (rsa_padding == RSA_X931_PADDING) {
335 padding_type = TLS_PADDING_RSA_X9_31;
336 } else { 332 } else {
337 goto err; 333 goto err;
338 } 334 }