-
Notifications
You must be signed in to change notification settings - Fork 112
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
RSA-PSS Warning #912
Comments
@Hagelkruys would you be willing to submit a PR to address this? |
I looked into creating an PR for this and found why the current implementation gives a warning for RSA-PSS. In the referenced mozilla root program (v2.7) there was a change that RSA-PSS is not allowed as id in the SubjectPublicKeyInfo field, thats also in the current mozilla root program policy and BR.
The linting file above checks for the SigningAlgorithm, that is another field. so there seams to be a mixup of SigningAlgorithm and SubjectPublicKeyInfo identifier |
I removed the warning and added the signature algorithm to the pass list. |
Hello,
if parsing a certificate with RSASSA-PSS Signing Algorithm the zlint gives a warning "e_signature_algorithm_not_supported"
In "\v3\lints\cabf_br\lint_signature_algorithm_not_supported.go" it states the following.
That isn't correct anymore.
On the contrary, you should not use RSA with PKCS1v1.5 anymore, see https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TG02102/BSI-TR-02102-1.pdf?__blob=publicationFile&v=6 - 1.5 Dealing with Legacy Algorithms - RSA with PKCS1v1.5 padding
The text was updated successfully, but these errors were encountered: