Skip to content

Update getSigAlgs to handle algorithms without combined NID - #1019

Open
eager-signal wants to merge 1 commit into
netty:mainfrom
eager-signal:sigalgs-ed25519
Open

eager-signal wants to merge 1 commit into
netty:mainfrom
eager-signal:sigalgs-ed25519

Conversation

@eager-signal

@eager-signal eager-signal commented Oct 1, 2026 •

Copy link
Copy Markdown

Motivation:

Some algorithms, such as Ed25519, have no combined signature and hash NID, causing them to be returned as NID_undef, and thus unusable to callers.

Modifications:

Fall back to psign if psignhash is undefined

Result:

Code point TLS name Before After
0x0807 ed25519 undefined ED25519
0x0808 ed448 undefined ED448
0x0804 rsa_pss_rsae_sha256 undefined rsassaPss
0x0805 rsa_pss_rsae_sha384 undefined rsassaPss
0x0806 rsa_pss_rsae_sha512 undefined rsassaPss
0x0809 rsa_pss_pss_sha256 undefined rsassaPss
0x080a rsa_pss_pss_sha384 undefined rsassaPss
0x080b rsa_pss_pss_sha512 undefined rsassaPss
0x0302 dsa_sha224 undefined dsaEncryption
0x0502 dsa_sha384 undefined dsaEncryption
0x0602 dsa_sha512 undefined dsaEncryption

@eager-signal

Copy link
Copy Markdown
Author

I‘m not sure if the duplicated/indistinguishable rsassaPss and dsaEncryption are acceptable.

@normanmaurer normanmaurer added this to the 2.0.85.Final milestone Oct 1, 2026
@normanmaurer
normanmaurer requested a review from chrisvest October 1, 2026 15:20
@normanmaurer

Copy link
Copy Markdown
Member

@davidben WDYT ?

Motivation:

Some algorithms, such as Ed25519, have no combined signature and hash NID, causing them
to be returned as NID_undef, and thus unusable to callers.

Modifications:

Fall back to `psign` if `psignhash` is undefined

Result:

| Code point | TLS name              | Before      | After           |
|------------|-----------------------|-------------|-----------------|
| `0x0807`   | `ed25519`             | `undefined` | `ED25519`       |
| `0x0808`   | `ed448`               | `undefined` | `ED448`         |
| `0x0804`   | `rsa_pss_rsae_sha256` | `undefined` | `rsassaPss`     |
| `0x0805`   | `rsa_pss_rsae_sha384` | `undefined` | `rsassaPss`     |
| `0x0806`   | `rsa_pss_rsae_sha512` | `undefined` | `rsassaPss`     |
| `0x0809`   | `rsa_pss_pss_sha256`  | `undefined` | `rsassaPss`     |
| `0x080a`   | `rsa_pss_pss_sha384`  | `undefined` | `rsassaPss`     |
| `0x080b`   | `rsa_pss_pss_sha512`  | `undefined` | `rsassaPss`     |
| `0x0302`   | `dsa_sha224`          | `undefined` | `dsaEncryption` |
| `0x0502`   | `dsa_sha384`          | `undefined` | `dsaEncryption` |
| `0x0602`   | `dsa_sha512`          | `undefined` | `dsaEncryption` |
@eager-signal

Copy link
Copy Markdown
Author

I‘m not sure if the duplicated/indistinguishable rsassaPss and dsaEncryption are acceptable.

To clarify; upstream, they would be a no-op, because SignatureAlgorithmConverter still wouldn’t parse them, but they might affect other library users.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants