Repository navigation
Conversation
For openssl_pkey_get_details we export the priv+pub parameters.
ED25519/ED448 do not support streaming, so we need to use
EVP_Digest{Sign,Verify} instead. In general the older EVP_{Sign,Verify}
interface should be avoided as the key is passed very late.
See BUGS section in OpenSSL manpages of EVP_{Sign,Verify}Final
Additionally per requirement we need to allow sign/verify without
digest. So we need to allow passing 0 as digest. In OpenSSL 3.0+ this also
corresponds to the default digest (see EVP_PKEY_get_default_digest_name).
For CSR creation we need to allow "null" as digest_alg option.
manuelm
force-pushed
the
openssl_25519_448
branch
from
April 26, 2024 11:27
ddbda9a to
2cf02ea
Compare
bukka
reviewed
Apr 28, 2024
Member
|
For the record I have tested the changes with OpenSSL 1.1.1, 3.0 and 3.3 and all was good. The code and tests are also good so I just merged it (with addition of UPGRADING and NEWS info) to master and it will be part of PHP 8.4. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
For
openssl_pkey_get_detailswe export the priv+pub parameters.ED25519/ED448 do not support streaming, so we need to use
EVP_Digest{Sign,Verify}instead. In general the olderEVP_{Sign,Verify}interface should be avoided as the key is passed very late. See BUGS section in OpenSSL manpages ofEVP_{Sign,Verify}FinalAdditionally per requirement we need to allow sign/verify without digest. So we need to allow passing 0 as digest. In OpenSSL 3.0+ this also corresponds to the default digest (see
EVP_PKEY_get_default_digest_name).For CSR creation we need to allow
nullasdigest_algoption.