diff --git a/openssl-classes/src/main/java/io/netty/internal/tcnative/SSL.java b/openssl-classes/src/main/java/io/netty/internal/tcnative/SSL.java index f28df2b61..f6a6dc631 100644 --- a/openssl-classes/src/main/java/io/netty/internal/tcnative/SSL.java +++ b/openssl-classes/src/main/java/io/netty/internal/tcnative/SSL.java @@ -876,7 +876,8 @@ public static void setKeyMaterialServerSide(long ssl, long chain, long key) thro /** * Return the signature algorithms that the remote peer supports or {@code null} if none are supported. * See man SSL_get_sigalgs for more details. - * The returned names are generated using {@code OBJ_nid2ln} with the {@code psignhash} as parameter. + * The returned names are generated using {@code OBJ_nid2ln} with the {@code psignhash} as parameter, or with + * {@code psign} if there is no {@code psignhash} (for example for Ed25519). * * @param ssl the SSL instance (SSL *) * @return the signature algorithms or {@code null}. diff --git a/openssl-dynamic/src/main/c/ssl.c b/openssl-dynamic/src/main/c/ssl.c index 3aec22371..59a894f92 100644 --- a/openssl-dynamic/src/main/c/ssl.c +++ b/openssl-dynamic/src/main/c/ssl.c @@ -2704,6 +2704,7 @@ TCN_IMPLEMENT_CALL(jobjectArray, SSL, getSigAlgs)(TCN_STDARGS, jlong ssl) { #if OPENSSL_VERSION_NUMBER >= 0x10002000L || defined(__GNUC__) || defined(__GNUG__) int i; int nsig; + int psign; int psignhash; jobjectArray array = NULL; jstring algString = NULL; @@ -2718,7 +2719,12 @@ TCN_IMPLEMENT_CALL(jobjectArray, SSL, getSigAlgs)(TCN_STDARGS, jlong ssl) { } for (i = 0; i < nsig; i++) { - SSL_get_sigalgs(ssl_, i, NULL, NULL, &psignhash, NULL, NULL); + SSL_get_sigalgs(ssl_, i, &psign, NULL, &psignhash, NULL, NULL); + if (psignhash == NID_undef) { + // Some algorithms, such as Ed25519, Ed448 and RSA-PSS, have no combined signature and hash NID. + // Use the signature NID so we return their name rather than "undefined". + psignhash = psign; + } if ((algString = (*e)->NewStringUTF(e, OBJ_nid2ln(psignhash))) == NULL) { // something is wrong we should better just return here return NULL;