Re: Chain building fails in version 1.1.1i if CA uses RSASSA-PSS for signing EE cert

2021-02-04 Thread Tomas Mraz
Hi, yes, this is a known regression in 1.1.1i that is fixed in the git repo already with commit c2fc1115eac53d2043e09bfa43ac5407f87fe417 Tomas On Thu, 2021-02-04 at 13:08 +0100, we...@infotech.de wrote: > Dear OpenSSL users, > > we just bumped into a case we assume as a bug in version 1.1.1i.

Chain building fails in version 1.1.1i if CA uses RSASSA-PSS for signing EE cert

2021-02-04 Thread weber
Dear OpenSSL users, we just bumped into a case we assume as a bug in version 1.1.1i. Building a (partial) chain fails if an enduser cert is signed by a ca using RSASSA-PSS algorithm. Chain building works with version 1.1.1g. Tracing the issue down, we found that the check_issued (source x509