[openssl-dev] [openssl-users] pkeyutl does not invoke hash?

Blumenthal, Uri - 0553 - MITLL uri at ll.mit.edu
Mon Feb 1 16:28:13 UTC 2016


On 2/1/16, 9:23 , "Hubert Kario" <hkario at redhat.com> wrote:

>On Wednesday 20 January 2016 17:17:47 Blumenthal, Uri - 0553 - MITLL
>wrote:
>> I see. Steve, what would you suggest to add to the man page, in view
>> of what we’ve been discussing for the last few days here?
>
>I've updated the pull request to state explicitly that no hashing will
>be done for RSA, ECDSA and DSA signature inputs.

Perfect! Thanks!!

>old proposed patch:
>https://github.com/tomato42/openssl/commit/f37b5e639e57c2d4c3b404c24ecb11b
>8ec627e9b
>new proposed patch:
>https://github.com/openssl/openssl/commit/02c0d466664126cf277a8d51b09863fa
>d55daf74

Rich, let’s percolate this to the OpenSSL_1_0_2-stable?




When EdDSA support is included in pkeyutl (and tested) - more text can be
added, describing what parameters *exactly* EdDSA takes, what they mean,
and how EdDSA processing differs from other signatures. This EdDSA change
would only go to the master.

Again, thank you!



>-- 
>Regards,
>Hubert Kario
>Senior Quality Engineer, QE BaseOS Security team
>Web: www.cz.redhat.com
>Red Hat Czech s.r.o., Purkyňova 99/71, 612 45, Brno, Czech Republic
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4308 bytes
Desc: not available
URL: <http://mta.openssl.org/pipermail/openssl-dev/attachments/20160201/4b00e315/attachment-0001.bin>


More information about the openssl-dev mailing list