Re: Using certificates and keys from a list
Viktor Dukhovni <[email protected]> Mon, 6 Apr 2026 16:41:42 +1000
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Apr 06, 2026 at 06:32:06AM +1000, Viktor Dukhovni wrote:
> The pkey_type data flow is bit non-obvious, the NID stays NID_undef for
> PKCS#8 keys (the norm), which can be decoded generically, otherwise it
> is set to a type-specific NID for type-specific PEM encodings:
>=20
> https://github.com/vdukhovni/postfix/blob/250e75ebd980eafa3ed5f25e1d9=
d6a896b794c2e/postfix/src/tls/tls_certkey.c#L363-L370
I should perhaps mention that similar (derived from the original version
in Postfix) code was recently added in OpenSSL, and will be part of the
4.0 release:
https://github.com/openssl/openssl/pull/30089
See:
https://github.com/openssl/openssl/blob/99f50faba8b2ea3cc9bf7174f5efbb7=
b9dbab6e1/apps/lib/apps.c#L1173-L1277
--=20
Viktor. =F0=9F=87=BA=F0=9F=87=A6 =D0=A1=D0=BB=D0=B0=D0=B2=D0=B0 =D0=A3=
=D0=BA=D1=80=D0=B0=D1=97=D0=BD=D1=96!
--=20
You received this message because you are subscribed to the Google Groups "=
openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msg=
id/openssl-users/adNVpo0dLrxLqafc%40chardros.imrryr.org.