Re: How do selfserv and tstclnt specify RSASSA-PSS certificate?

Martin Thomson <[email protected]>
Newsgroups gmane.comp.mozilla.crypto
Message-ID <CAPLxc=VAGYSEK90+jm7KksC3bn2eGha-0TEw2wqtR25Kvu8PZQ@mail.gmail.com>
This was a feature we supported, but we have an open item to restore
full PSS support for TLS after some changes in TLS 1.3 reassigned the
meaning of the codepoints.  (It's been a few months, and a low
priority item, but it is still on my todo list).  Getting selfserv and
tstclnt to use those keys requires the stack to support them fully,
which - right now - it doesn't.
On Thu, May 31, 2018 at 2:31 AM John Jiang <[email protected]> wrote:
>
> Hi,
> I'm using NSS 3.37.
>
> Tried to specify a RSASSA-PSS certificate for selfserv and tstclnt, but
> looks no option supports this certificate type: "Must specify at least one
> certificate nickname using '-n' (RSA), '-S' (DSA), or 'e' (EC)."
> But it looks the current NSS supports RSASSA-PSS.
> --
> dev-tech-crypto mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-tech-crypto
-- 
dev-tech-crypto mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-tech-crypto
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.