set correct signarue digest name when using ECDSA cert#127
Open
outsinre wants to merge 1 commit intoleafo:masterfrom
Open
set correct signarue digest name when using ECDSA cert#127outsinre wants to merge 1 commit intoleafo:masterfrom
outsinre wants to merge 1 commit intoleafo:masterfrom
Conversation
`lua-resty-openssl` is bumped to 0.8.10.
1 task
|
What's needed here to get this merged? @leafo can you please take a look? |
|
Just an update that this also fixes when the signature is RSA-SHA1. If we want to stay closer to what postgres does, instead of objects.txt2nid(signature) we could directly do server_cert.get_signature_nid(). |
Owner
|
This code is only compatible with openresty, not the other socket layers. Additionally it looks like the test suite did not run, does it need to be rebased to pick up the latest workflow? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When using ECDSA certificate, the
signaturename is the full name (e.g.,ecdsa-with-SHA384), but indeed should be the digest part only (e.g.,SHA384).This PR fixes the issue. Make sure
lua-resty-opensslis bumped to0.8.10.