Hi Steve, all,

Thus wrote Dr. Stephen Henson ([email protected]):

> I haven't had time to review the patch in much detail but I suspected
> some things like that might happen due to the way some
> AlgorithmIdentifiers were handled. I'm fairly sure it wouldn't work
> with a PSS only key too (which is treated as a different public key
> algorithm).

could you give me a pointer to where this is defined or a sample key,
certificate I could have a look at?

> If you can send some PSS certificates that would be great. I'm always
> happier if I've some data to interop test with.

I've just updated the sample certificates on

http://www.kaiser.cx/x509Pss.html

Hopefully, the explicit tagging for the pss parameters is ok now.

Best regards,

   Martin
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [email protected]
Automated List Manager                           [email protected]

Reply via email to