[gnutls-help] generating self signed cert - no way to set spki

Curtis Villamizar curtis at ipv6.occnc.com
Wed Aug 26 07:48:41 CEST 2020


That is OK if using RSA.  Doesn't help with EC CA certs.

Curtis


In message <87y2m1cyck.fsf-ueno at gnu.org>
Daiki Ueno writes:
> 
> Hello Curtis,
>  
> Curtis Villamizar <curtis at ipv6.occnc.com> writes:
>  
> There are quite a lot here and I can't tell what is the root cause until
> I see the code.  Would it be possible to provide a standalone
> reproducer?
>  
> > So there are two issues here:
> >
> >   1.  No way to fill in a spki struct.  I may be missing something.
>  
> This one is easy to answer: you can use gnutls_x509_spki_init,
> gnutls_x509_spki_set_rsa_pss_params, and gnutls_x509_spki_deinit.
>  
> Regards,
> -- 
> Daiki Ueno



More information about the Gnutls-help mailing list