Daiki Ueno ueno at gnu.org
Thu Aug 27 13:26:13 CEST 2020

Curtis Villamizar <curtis at ipv6.occnc.com> writes:

> That is OK if using RSA.  Doesn't help with EC CA certs.

Yes, because the gnutls_x509_spki_t structure was introduced to cover
the use-case of RSA-PSS.  The question is why you determine that it's
the cause of the failure you are facing; if you are dealing with EC
certs, that structure shouldn't be used at all.  That's why I'm asking
for a reproducer.

Aren't you able to achieve the same task with certtool either?

