Issue with EVP_sha256 and Tspi_Context_CreateObject

Swamy J-S swamy.j-s at in.abb.com
Mon Jun 10 11:52:15 UTC 2019


Hi,

Earlier with openssl 1.0.2n version, I was using EVP_sha256 for creating Certificate Signing Request  and "TSS_HASH_OTHER" flag in Tspi_Context_CreateObject.

Recently I upgraded openssl to 1.1.0g version and now am getting "Signature Verify Failure" in my CSR. I have attached the screenshot here

If I use EVP_sha1 and TSS_HASH_SHA1, then I am able to generate certificate but if it fails in TLS Handshake with my HTTPS Server.

Are there any changes in openssl engine structure with respect to Signing and private key encryption in openssl 1.1.0?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mta.openssl.org/pipermail/openssl-users/attachments/20190610/bbf34a2e/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: Untitled.png
Type: image/png
Size: 37358 bytes
Desc: Untitled.png
URL: <http://mta.openssl.org/pipermail/openssl-users/attachments/20190610/bbf34a2e/attachment-0001.png>


More information about the openssl-users mailing list