[gnutls-devel] GnuTLS | PKCS#11: RSA-PSS should be enabled only when the private key can be used for signing (#667)

Development of GNU's TLS library gnutls-devel at lists.gnutls.org
Fri Jan 4 15:00:07 CET 2019


Note that I have worked around this in OpenConnect thus: 
https://gitlab.com/openconnect/openconnect/merge_requests/23/diffs?commit_id=04bcebbc0658fdf36aa9b6572fdc529b74d751f5

The approach I've taken there covers all kinds of hardware keys, including TPM keys which may or may not support RSA-PSS. It just attempts to perform a RSA-PSS signature and then disables TLSv1.3 if that fails.

-- 
Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/issues/667#note_128984089
You're receiving this email because of your account on gitlab.com.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.gnupg.org/pipermail/gnutls-devel/attachments/20190104/36a10eb0/attachment.html>


More information about the Gnutls-devel mailing list