[gnutls-devel] GnuTLS | PKCS#11: RSA-PSS should be enabled only when the private key can be used for signing (#667)
Development of GNU's TLS library
gnutls-devel at lists.gnutls.org
Fri Jan 4 15:00:07 CET 2019
Note that I have worked around this in OpenConnect thus:
The approach I've taken there covers all kinds of hardware keys, including TPM keys which may or may not support RSA-PSS. It just attempts to perform a RSA-PSS signature and then disables TLSv1.3 if that fails.
Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/issues/667#note_128984089
You're receiving this email because of your account on gitlab.com.
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Gnutls-devel