• B
    Propagate TLS 1.3 sigalgs through tls1_set_sigalgs() · fd5e1a8c
    Benjamin Kaduk 提交于
    Our historical SSL{,_CTX}_set_sigalgs() APIs take an array of
    NID pairs (hash and signature), and our parser for manually
    specifying unified sigalgs (that do not necessarily correspond
    to an actual signature+hash pair) was transiting via (the implementation
    of) this historical API.  The TLS 1.3 draft-23 has introduced
    signature schemes that have identical signature type and hash type,
    differing only in the (RSA) public key OID, which prevents
    the rsa_pss_pss_* schemes from being properly identified and
    sent on the wire.
    
    To fix the issue, parse sigalg strings directly into SIGALG_LOOKUP
    objects, and pass around an array of uint16 wire protocol values
    instead of NID pairs.  The old interface is retained for API
    compatibility but will become less and less useful with time.
    Reviewed-by: NMatt Caswell <matt@openssl.org>
    (Merged from https://github.com/openssl/openssl/pull/5068)
    fd5e1a8c
ssl_locl.h 97.6 KB